diff --git a/src/mas/devops/data/catalogs/v9-261007-amd64.yaml b/src/mas/devops/data/catalogs/v9-261007-amd64.yaml new file mode 100644 index 00000000..bb75b9cd --- /dev/null +++ b/src/mas/devops/data/catalogs/v9-261007-amd64.yaml @@ -0,0 +1,209 @@ +--- +# Case bundle configuration for IBM Maximo Operator Catalog 261007 (AMD64) +# ----------------------------------------------------------------------------- +# In the future this won't be necessary as we'll be able to mirror from the +# catalog itself, but not everything in the catalog supports this yet (including MAS) +# so we need to use the CASE bundle mirror process still. + +catalog_digest: sha256:48853583aafe1351ac766c50f5297c67015751269c476de31c2b9bfe66e29d8f + +ocp_compatibility: +- "4.18" +- "4.19" +- "4.20" +- "4.21" +- "4.22" + +# Dependencies - Cloud Pak for Data +# ----------------------------------------------------------------------------- +cpd_product_version_default: 5.3.1 # No Updated + +# Dependencies +# ----------------------------------------------------------------------------- +ibm_licensing_version: 4.2.24 # Operator version 4.2.20 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-licensing) +common_svcs_version: 4.17.0 # Operator version 4.17.0 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-cp-common-services) +#common_svcs_version_1: 4.11.0 # Additional version 4.11.0 + +cp4d_platform_version: 5.4.0+20260501.120952.925.640.50 # Operator version 5.4.0 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-cp-datacore/) +ibm_zen_version: 6.4.0+20260210.170932.92 # For CPD5 ibm-zen has to be explicitily mirrored + +# CPD 5.3.1 Helm Component Versions (CASE versions For Helm charts) +wsl_version: 12.1.0 # CPD 5.3.1 Watson Studio CASE version for Helm +wsl_runtimes_version: 12.1.0 # CPD 5.3.1 Watson Studio Runtimes CASE version +wml_version: 12.1.0 # CPD 5.3.1 Watson Machine Learning CASE version for Helm +redis_version: 1.3.1 # CPD 5.3.1 Redis CASE version (WML dependency) +postgress_version: 5.31.0+20260129.161021.2713 # ibm-cpd-cloud-native-postgresql-operator 5.2.0 cp4d + +# CPD 5.3.1 Shared Dependencies +ccs_build: 12.1.0 # CPD 5.3.1 Common Core Services CASE version +opensearch_version: 1.2.0 # CPD 5.3.1 OpenSearch CASE version +datarefinery_version: 12.1.0 # CPD 5.3.1 Data Refinery CASE version + +spark_version: 12.1.0 # CPD 5.3.1 Analytics Engine/Spark CASE version for Helm +cognos_version: 29.1.0 # CPD 5.3.1 Cognos Analytics CASE version for Helm (Helm-only) +elasticsearch_version: 1.1.2667 + + +# Dependencies - Db2u +# ----------------------------------------------------------------------------- +db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) +db2u_extras_version: 1.0.6 +db2u_filter: db2 + +db2_channel_default: v120105.0 # No Updated # Default Channel version for db2u-operator + + +# Dependencies - CouchDb +# ----------------------------------------------------------------------------- +# Note: This is required for Assist 9.0 (https://github.com/IBM/cloud-pak/blob/master/repo/case/ibm-couchdb/index.yaml) +couchdb_version: 1.0.13 # Operator version 2.2.1 (1.0.13) sticking with 1.0.13 + + +# Dependencies - Minio +# ----------------------------------------------------------------------------- +minio_version: RELEASE.2025-06-13T11-33-47Z +minio_extras_version: 1.0.0 + +# Dependencies - MongoDB +# ----------------------------------------------------------------------------- +mongo_extras_version_default: 8.0.30 +mongo_extras_version_4: 4.4.21 +mongo_extras_version_5: 5.0.23 +mongo_extras_version_6: 6.0.12 +mongo_extras_version_7: 7.0.23 +mongo_extras_version_8: 8.0.30 # No Update + + +# Dependencies - Amlen +# ----------------------------------------------------------------------------- +amlen_extras_version: 1.1.6 # No Update + + +# Dependencies - UDS +# ----------------------------------------------------------------------------- +uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change +uds_extras_version: 1.5.0 + + +# Dependencies - App Connect +# ----------------------------------------------------------------------------- +appconnect_version: 6.2.0 # Operator version 6.2.0 # sticking to 6.2.0 version # Please do Not Change + + +# Dependencies - Suite License Service +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-sls/releases +sls_version: 3.13.2 # No Update + + +# Dependencies - Truststore Manager +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases +tsm_version: 1.7.9 # No Update + + +# Dependencies - Data Dictionary +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-data-dictionary/releases +dd_version: 1.1.23 # No Update + +# Dependencies - Opendata hub +# ----------------------------------------------------------------------------- +# https://github.com/opendatahub-io/opendatahub-operator/releases +odh_version: 2.32.0 + +# Extra Images for Redis (Collaborate) +# ------------------------------------------------------------------------------ +redis_extras_version: 2.1.40 # No Update + + +# Maximo Application Suite +# ----------------------------------------------------------------------------- +mas_core_version: + 9.2.x: 9.2.8 # Updated + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.27 # Updated + 9.0.x: 9.0.33 # Updated + 8.10.x: 8.10.37 # No Update + 8.11.x: 8.11.34 # No Update +mas_assist_version: + 9.1.x: 9.1.15 # No Update + 9.0.x: 9.0.21 # No Update + 8.10.x: 8.7.8 # No Update + 8.11.x: 8.8.7 # No Update +mas_hputilities_version: + 9.1.x: "" # Not Supported + 9.0.x: "" # Not Supported + 8.10.x: 8.6.7 # No Update + 8.11.x: "" # Not Supported +mas_iot_version: + 9.2.x: 9.2.4 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.15 # No Update + 9.0.x: 9.0.24 # No Update + 8.10.x: 8.7.33 # No Update + 8.11.x: 8.8.30 # No Update +mas_manage_version: + 9.2.x: 9.2.4 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.25 # No Update + 9.0.x: 9.0.32 # No Update + 8.10.x: 8.6.38 # No Update + 8.11.x: 8.7.32 # No Update +mas_monitor_version: + 9.2.x: 9.2.4 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.15 # No Update + 9.0.x: 9.0.25 # No Update + 8.10.x: 8.10.30 # No Update + 8.11.x: 8.11.28 # No Update +mas_optimizer_version: + 9.2.x: 9.2.3 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.16 # No Update + 9.0.x: 9.0.27 # No Update + 8.10.x: 8.4.28 # No Update + 8.11.x: 8.5.28 # No Update +mas_predict_version: + 9.2.x: 9.2.2 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.11 # No Update + 9.0.x: 9.0.18 # No Update + 8.10.x: 8.8.15 # No Update + 8.11.x: 8.9.17 # No Update +mas_visualinspection_version: + 9.2.x: 9.2.3 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.21 # No Update + 9.0.x: 9.0.24 # No Update + 8.10.x: 8.8.4 # No Update + 8.11.x: 8.9.21 # No Update +mas_facilities_version: + 9.2.x: 9.2.3 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.15 # No Update + 9.0.x: "" # Not Supported + 8.10.x: "" # Not Supported + 8.11.x: "" # Not Supported + + +# Maximo AI Service +# ------------------------------------------------------------------------------ +aiservice_version: + 9.2.x: 9.2.3 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.19 # No Update + +aiservice_tenant_version: + 9.2.x: 9.2.3 # No Update + 9.2.x-feature: 9.2.0 # No Update + + +# Editorial +# ------------------------------------------------------------------------------ +editorial: + whats_new: + - title: '**Security updates and bug fixes**' + details: + - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 + - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] diff --git a/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml b/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml new file mode 100644 index 00000000..b2088dd6 --- /dev/null +++ b/src/mas/devops/data/catalogs/v9-261007-ppc64le.yaml @@ -0,0 +1,76 @@ +--- +# Case bundle configuration for IBM Maximo Operator Catalog 261007 (PPC) +# ----------------------------------------------------------------------------- +# In the future this won't be necessary as we'll be able to mirror from the +# catalog itself, but not everything in the catalog supports this yet (including MAS) +# so we need to use the CASE bundle mirror process still. + +catalog_digest: sha256:910e5b3d32711686e12044d95a51c200379ae46eea3a0ed3e8b85a912aa0ac69 + +ocp_compatibility: +- "4.18" +- "4.19" +- "4.20" +- "4.21" +- "4.22" + +# Dependencies - Db2u +# ----------------------------------------------------------------------------- +db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) + +db2_channel_default: v120105.0 # No Updated # Default Channel version for db2u-operator + + +# Dependencies - UDS +# ----------------------------------------------------------------------------- +uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change +uds_extras_version: 1.5.0 # No Update + + +# Dependencies - Suite License Service +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-sls/releases +sls_version: 3.13.2 # No Update + + +# Dependencies - Truststore Manager +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases +tsm_version: 1.7.9 # No Update + + +# Dependencies - MongoDB +# ----------------------------------------------------------------------------- +mongo_extras_version_default: 8.0.30 +mongo_extras_version_4: 4.4.21 +mongo_extras_version_5: 5.0.23 +mongo_extras_version_6: 6.0.12 +mongo_extras_version_7: 7.0.12 +mongo_extras_version_8: 8.0.30 # No Update + +# Maximo Application Suite +# ----------------------------------------------------------------------------- +mas_core_version: + 9.2.x: 9.2.8 # Updated + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.27 # Updated + 9.0.x: 9.0.33 # Updated + 8.10.x: "" # Not Supported + 8.11.x: "" # Not Supported +mas_manage_version: + 9.2.x: 9.2.4 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.25 # No Update + 9.0.x: 9.0.32 # No Update + 8.10.x: "" # Not Supported + 8.11.x: "" # Not Supported + + +# Editorial +# ------------------------------------------------------------------------------ +editorial: + whats_new: + - title: '**Security updates and bug fixes**' + details: + - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 + - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] \ No newline at end of file diff --git a/src/mas/devops/data/catalogs/v9-261007-s390x.yaml b/src/mas/devops/data/catalogs/v9-261007-s390x.yaml new file mode 100644 index 00000000..ba932848 --- /dev/null +++ b/src/mas/devops/data/catalogs/v9-261007-s390x.yaml @@ -0,0 +1,76 @@ +--- +# Case bundle configuration for IBM Maximo Operator Catalog 261007 (Z) +# ----------------------------------------------------------------------------- +# In the future this won't be necessary as we'll be able to mirror from the +# catalog itself, but not everything in the catalog supports this yet (including MAS) +# so we need to use the CASE bundle mirror process still. + +catalog_digest: sha256:0654a9b9cc9b1304b3314dbde457548bfae322c4f2f962971212a15cb2bce7de + +ocp_compatibility: +- "4.18" +- "4.19" +- "4.20" +- "4.21" +- "4.22" + +# Dependencies - Db2u +# ----------------------------------------------------------------------------- +db2u_version: 7.7.1+20260729.095150.20860 # Operator version 120105.0.1 (https://github.com/IBM/cloud-pak/tree/master/repo/case/ibm-db2uoperator) + +db2_channel_default: v120105.0 # No Update # Default Channel version for db2u-operator + + +# Dependencies - UDS +# ----------------------------------------------------------------------------- +uds_version: 2.0.12 # Operator version 2.0.12 # sticking to 2.0.12 version # Please do Not Change +uds_extras_version: 1.5.0 # No Update + + +# Dependencies - Suite License Service +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-sls/releases +sls_version: 3.13.2 # No Update + + +# Dependencies - Truststore Manager +# ----------------------------------------------------------------------------- +# https://github.ibm.com/maximoappsuite/ibm-truststore-mgr/releases +tsm_version: 1.7.9 # No Update + + +# Dependencies - MongoDB +# ----------------------------------------------------------------------------- +mongo_extras_version_default: 8.0.30 +mongo_extras_version_4: 4.4.21 +mongo_extras_version_5: 5.0.23 +mongo_extras_version_6: 6.0.12 +mongo_extras_version_7: 7.0.12 +mongo_extras_version_8: 8.0.30 # No Update + +# Maximo Application Suite +# ----------------------------------------------------------------------------- +mas_core_version: + 9.2.x: 9.2.8 # Updated + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.27 # Updated + 9.0.x: 9.0.33 # Updated + 8.10.x: "" # Not Supported + 8.11.x: "" # Not Supported +mas_manage_version: + 9.2.x: 9.2.4 # No Update + 9.2.x-feature: 9.2.0 # No Update + 9.1.x: 9.1.25 # No Update + 9.0.x: 9.0.32 # No Update + 8.10.x: "" # Not Supported + 8.11.x: "" # Not Supported + + +# Editorial +# ------------------------------------------------------------------------------ +editorial: + whats_new: + - title: '**Security updates and bug fixes**' + details: + - Security fix available for CVE-2026-105052 (Path Traversal, CVSS 7.5) Details: https://www.ibm.com/support/pages/node/7289766 + - IBM Maximo Application Suite Core Platform [v9.0.33], [v9.1.27] and [v9.2.8] \ No newline at end of file diff --git a/src/mas/devops/tekton.py b/src/mas/devops/tekton.py index ed44dc4e..e017a3dd 100644 --- a/src/mas/devops/tekton.py +++ b/src/mas/devops/tekton.py @@ -843,30 +843,17 @@ def prepareAiServicePipelinesNamespace( logger.info(f"Storage class {storageClass} uses volumeBindingMode={volumeBindingMode}, skipping PVC bind wait") -def prepareRestoreSecrets( - dynClient: DynamicClient, - namespace: str, - restoreConfigs: dict = None, - ibm_entitlement_key: str = None, - artifactory_token: str = None, - artifactory_username: str = None, - registry_secret_name: str = "mas-restore-secrets", -): +def prepareRestoreSecrets(dynClient: DynamicClient, namespace: str, restoreConfigs: dict = None): """ Create or update secret required for MAS Restore pipeline. - Creates secrets in the specified namespace: + Creates secret in the specified namespace: - pipeline-restore-configs - - {registry_secret_name} (only when credentials are provided) Parameters: dynClient (DynamicClient): OpenShift Dynamic Client namespace (str): The namespace to create secrets in restoreConfigs (dict, optional): configuration data for restore. Defaults to None (empty secret). - ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None. - artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. - artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. - registry_secret_name (str, optional): Name of the per-pipeline registry credentials secret. Defaults to "mas-restore-secrets". Returns: None @@ -893,37 +880,6 @@ def prepareRestoreSecrets( } secretsAPI.create(body=restoreConfigs, namespace=namespace) - # 2. Secret/{registry_secret_name} - # ------------------------------------------------------------------------- - credentials_data = {} - - if ibm_entitlement_key: - credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() - - if artifactory_token: - credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - - if artifactory_username: - credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - if credentials_data: - try: - secretsAPI.delete(name=registry_secret_name, namespace=namespace) - except NotFoundError: - pass - - secretsAPI.create( - body={ - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": registry_secret_name}, - "data": credentials_data, - }, - namespace=namespace, - ) - logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") - def prepareInstallSecrets( dynClient: DynamicClient, @@ -937,18 +893,13 @@ def prepareInstallSecrets( aiserviceConfig: str = None, db2LicenseFile: dict | None = None, facilitiesProperties: dict | None = None, - ibm_entitlement_key: str = None, - artifactory_token: str = None, - artifactory_username: str = None, - registry_secret_name: str = None, ) -> None: """ Create or update secrets required for MAS installation pipelines. - Creates secrets in the specified namespace: mas-devops-slack, {registry_secret_name}, - pipeline-additional-configs, pipeline-sls-entitlement, pipeline-certificates, - pipeline-pod-templates, pipeline-aiservice-config, pipeline-db2-license, and - pipeline-facilities-properties. + Creates secrets in the specified namespace: mas-devops-slack, pipeline-additional-configs, + pipeline-sls-entitlement, pipeline-certificates, pipeline-pod-templates, pipeline-aiservice-config, + pipeline-db2-license, and pipeline-facilities-properties. Parameters: dynClient (DynamicClient): OpenShift Dynamic Client @@ -962,9 +913,6 @@ def prepareInstallSecrets( slack_channel (str, optional): Slack channel ID for notifications. Defaults to None. aiserviceConfig (str, optional): AI Service tenant config data. Defaults to None (empty secret). facilitiesProperties (dict, optional): Facilities properties file content. Defaults to None (empty secret). - ibm_entitlement_key (str, optional): IBM entitlement key for registry access. Defaults to None. - artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. - artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. Returns: None @@ -1011,46 +959,6 @@ def prepareInstallSecrets( secretsAPI.create(body=mas_devops_secret, namespace=namespace) logger.info(f"Created mas-devops-slack secret with MAS_INSTANCE_ID={instance_id} in namespace {namespace}") - # 1. Secret/{registry_secret_name} - # ------------------------------------------------------------------------- - # Per-pipeline secret holding registry credentials sourced from secret instead of pipeline params. - # Only created when at least one credential is provided — all keys are optional. - # Secret name is derived from namespace prefix if not explicitly provided: - # mas-{id}-pipelines → mas-install-secrets - # aiservice-{id}-pipelines → mas-aiservice-install-secrets - if instance_id: - if registry_secret_name is None: - registry_secret_name = "mas-aiservice-install-secrets" if namespace.startswith("aiservice-") else "mas-install-secrets" - - credentials_data = {} - - if ibm_entitlement_key: - credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() - - if artifactory_token: - credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - - if artifactory_username: - credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - if credentials_data: - try: - secretsAPI.delete(name=registry_secret_name, namespace=namespace) - except NotFoundError: - pass - - secretsAPI.create( - body={ - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": registry_secret_name}, - "data": credentials_data, - }, - namespace=namespace, - ) - logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") - # 1. Secret/pipeline-additional-configs # ------------------------------------------------------------------------- # Must exist, but can be empty @@ -1166,24 +1074,17 @@ def prepareUpdateSecrets( slack_token: str = None, slack_channel: str = None, db2LicenseFile: dict | None = None, - artifactory_token: str = None, - artifactory_username: str = None, - registry_secret_name: str = "mas-update-secrets", ) -> None: """ Create or update mas-devops-slack secret in mas-pipelines namespace for update pipeline. Creates the slack secret in mas-pipelines namespace if it exists and slack credentials are provided. - Also creates {registry_secret_name} secret if artifactory credentials are provided. Parameters: dynClient (DynamicClient): OpenShift Dynamic Client slack_token (str, optional): Slack bot token for notifications. Defaults to None. slack_channel (str, optional): Slack channel ID for notifications. Defaults to None. db2LicenseFile (dict, optional): Db2 license file content. Defaults to None (empty secret). - artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. - artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. - registry_secret_name (str, optional): Name of the per-pipeline registry credentials secret. Defaults to "mas-update-secrets". Returns: None @@ -1251,95 +1152,6 @@ def prepareUpdateSecrets( secretsAPI.create(body=mas_devops_secret, namespace=namespace) logger.info(f"Created mas-devops-slack secret in namespace {namespace}") - # Create {registry_secret_name} if artifactory credentials are provided - # Note: update pipeline does not use ibm_entitlement_key (skipped via skip_entitlement_key_flag) - credentials_data = {} - - if artifactory_token: - credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - - if artifactory_username: - credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - if credentials_data: - try: - secretsAPI.delete(name=registry_secret_name, namespace=namespace) - except NotFoundError: - pass - - secretsAPI.create( - body={ - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": registry_secret_name}, - "data": credentials_data, - }, - namespace=namespace, - ) - logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") - - -def prepareUpgradeSecrets( - dynClient: DynamicClient, - namespace: str, - ibm_entitlement_key: str = None, - artifactory_token: str = None, - artifactory_username: str = None, - registry_secret_name: str = "mas-upgrade-secrets", -) -> None: - """ - Create the registry credentials secret required for the MAS Upgrade pipeline. - - Upgrade tasks pull images from ICR (ibm_entitlement_key) and optionally from - Artifactory (artifactory_token / artifactory_username). Credentials are written - into a named OCP Secret so they are never visible as plaintext PipelineRun params. - - Only keys with non-empty values are written to the secret. - The secret is skipped entirely if no credentials are provided. - - Parameters: - dynClient (DynamicClient): OpenShift Dynamic Client - namespace (str): The pipeline namespace (mas-{instanceId}-pipelines) - ibm_entitlement_key (str, optional): IBM entitlement key for ICR image pulls. Defaults to None. - artifactory_token (str, optional): Artifactory token for dev catalog access. Defaults to None. - artifactory_username (str, optional): Artifactory username for dev catalog access. Defaults to None. - registry_secret_name (str, optional): Name of the secret to create. Defaults to "mas-upgrade-secrets". - - Returns: - None - """ - secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") - - credentials_data = {} - - if ibm_entitlement_key: - credentials_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() - - if artifactory_token: - credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - - if artifactory_username: - credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - if credentials_data: - try: - secretsAPI.delete(name=registry_secret_name, namespace=namespace) - except NotFoundError: - pass - - secretsAPI.create( - body={ - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": registry_secret_name}, - "data": credentials_data, - }, - namespace=namespace, - ) - logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") - def testCLI() -> None: pass @@ -1374,6 +1186,63 @@ def testCLI() -> None: # fi +def prepareUpgradeSecrets( + dynClient: DynamicClient, + namespace: str, + ibm_entitlement_key: str = None, + artifactory_token: str = None, + artifactory_username: str = None, +) -> None: + """Create or update the registry credentials secret for MAS upgrade pipelines. + + Creates a secret named 'mas-secrets' in the specified namespace containing the + IBM entitlement key and Artifactory credentials used by Tekton task steps + via the task_registry_secret_name parameter. + + Args: + dynClient (DynamicClient): OpenShift Dynamic Client. + namespace (str): The pipelines namespace (format: mas-{instance_id}-pipelines). + ibm_entitlement_key (str, optional): IBM Entitled Registry pull key. Defaults to None. + artifactory_token (str, optional): Artifactory API token. Defaults to None. + artifactory_username (str, optional): Artifactory username. Defaults to None. + + Returns: + None + + Raises: + NotFoundError: If the secret cannot be created in the namespace. + """ + import base64 + + secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") + + secret_name = "mas-secrets" + + # Delete existing secret if it exists + try: + secretsAPI.delete(name=secret_name, namespace=namespace) + except NotFoundError: + pass + + secret_data = {} + if ibm_entitlement_key: + secret_data["IBM_ENTITLEMENT_KEY"] = base64.b64encode(ibm_entitlement_key.encode()).decode() + if artifactory_token: + secret_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() + if artifactory_username: + secret_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() + + secret_body = { + "apiVersion": "v1", + "kind": "Secret", + "type": "Opaque", + "metadata": {"name": secret_name}, + "data": secret_data, + } + secretsAPI.create(body=secret_body, namespace=namespace) + logger.info(f"Created {secret_name} secret in namespace {namespace}") + + def launchUpgradePipeline( dynClient: DynamicClient, instanceId: str, @@ -1551,63 +1420,6 @@ def launchUpdatePipeline(dynClient: DynamicClient, params: dict) -> str: return pipelineURL -def prepareBackupSecrets( - dynClient: DynamicClient, - namespace: str, - artifactory_token: str = None, - artifactory_username: str = None, - registry_secret_name: str = "mas-backup-secrets", -) -> None: - """ - Create the registry credentials secret required for the MAS Backup pipeline. - - Backup tasks do not use ibm_entitlement_key (no image pulls from ICR), but may - use Artifactory credentials to upload backup archives to an Artifactory repository. - Credentials are written into a named OCP Secret so they are never visible as - plaintext PipelineRun params. - - Only keys with non-empty values are written to the secret. - The secret is skipped entirely if no credentials are provided. - - Parameters: - dynClient (DynamicClient): OpenShift Dynamic Client - namespace (str): The pipeline namespace (mas-{instanceId}-pipelines) - artifactory_token (str, optional): Artifactory token for archive upload. Defaults to None. - artifactory_username (str, optional): Artifactory username for archive upload. Defaults to None. - registry_secret_name (str, optional): Name of the secret to create. Defaults to "mas-backup-secrets". - - Returns: - None - """ - secretsAPI = dynClient.resources.get(api_version="v1", kind="Secret") - - credentials_data = {} - - if artifactory_token: - credentials_data["ARTIFACTORY_TOKEN"] = base64.b64encode(artifactory_token.encode()).decode() - - if artifactory_username: - credentials_data["ARTIFACTORY_USERNAME"] = base64.b64encode(artifactory_username.encode()).decode() - - if credentials_data: - try: - secretsAPI.delete(name=registry_secret_name, namespace=namespace) - except NotFoundError: - pass - - secretsAPI.create( - body={ - "apiVersion": "v1", - "kind": "Secret", - "type": "Opaque", - "metadata": {"name": registry_secret_name}, - "data": credentials_data, - }, - namespace=namespace, - ) - logger.info(f"Created {registry_secret_name} secret in namespace {namespace}") - - def launchBackupPipeline(dynClient: DynamicClient, params: dict) -> str: """ Create a PipelineRun to backup a MAS instance. diff --git a/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 b/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 index d340ce8d..4b5bc70c 100644 --- a/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-aiservice-upgrade.yml.j2 @@ -15,11 +15,6 @@ spec: pipeline: "0" params: - # Registry Credentials Secret - # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name - value: "mas-aiservice-upgrade-secrets" - # Target AI Service Instance # ------------------------------------------------------------------------- - name: aiservice_instance_id @@ -27,12 +22,27 @@ spec: - name: aiservice_channel value: "{{ aiservice_channel }}" + # IBM Entitlement Key + # ------------------------------------------------------------------------- + - name: ibm_entitlement_key + value: "{{ ibm_entitlement_key }}" + {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- - name: skip_pre_check value: "{{ skip_pre_check }}" {%- endif %} +{%- if artifactory_username is defined and artifactory_username != "" %} + + # Enable development catalogs + # ------------------------------------------------------------------------- + - name: artifactory_username + value: "{{ artifactory_username }}" + - name: artifactory_token + value: "{{ artifactory_token }}" +{%- endif %} + workspaces: # The generated configuration files # ------------------------------------------------------------------------- diff --git a/src/mas/devops/templates/pipelinerun-backup.yml.j2 b/src/mas/devops/templates/pipelinerun-backup.yml.j2 index 3019ef70..d5386710 100644 --- a/src/mas/devops/templates/pipelinerun-backup.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-backup.yml.j2 @@ -17,11 +17,6 @@ spec: persistentVolumeClaim: claimName: backup-pvc params: - # Registry Credentials Secret - # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name - value: "mas-backup-secrets" - # Common Parameters - name: image_pull_policy value: IfNotPresent @@ -79,6 +74,16 @@ spec: value: "{{ cert_manager_provider }}" {% endif %} + # Development Build Support + {% if artifactory_username is defined and artifactory_username != "" %} + - name: artifactory_username + value: "{{ artifactory_username }}" + {% endif %} + {% if artifactory_token is defined and artifactory_token != "" %} + - name: artifactory_token + value: "{{ artifactory_token }}" + {% endif %} + # Upload Configuration {% if upload_backup is defined and upload_backup != "" %} - name: upload_backup diff --git a/src/mas/devops/templates/pipelinerun-install.yml.j2 b/src/mas/devops/templates/pipelinerun-install.yml.j2 index eb422e8e..ca6dd277 100644 --- a/src/mas/devops/templates/pipelinerun-install.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-install.yml.j2 @@ -19,15 +19,10 @@ spec: pipeline: "0" params: - # Registry Credentials Secret + # IBM Entitlement Key # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name -{%- if mas_instance_id is defined and mas_instance_id != "" %} - value: "mas-install-secrets" -{%- else %} - value: "mas-aiservice-install-secrets" -{%- endif %} - + - name: ibm_entitlement_key + value: "{{ ibm_entitlement_key }}" {%- if skip_pre_check is defined and skip_pre_check != "" %} # Pipeline config @@ -49,6 +44,15 @@ spec: - name: ocp_ingress_tls_secret_name value: "{{ ocp_ingress_tls_secret_name }}" {%- endif %} +{%- if artifactory_username is defined and artifactory_username != "" %} + + # Enable development catalogs + # ------------------------------------------------------------------------- + - name: artifactory_username + value: "{{ artifactory_username }}" + - name: artifactory_token + value: "{{ artifactory_token }}" +{%- endif %} {%- if ibmcloud_apikey is defined and ibmcloud_resourcegroup != "" %} # IBM Cloud diff --git a/src/mas/devops/templates/pipelinerun-restore.yml.j2 b/src/mas/devops/templates/pipelinerun-restore.yml.j2 index 10654533..bf5ae6fa 100644 --- a/src/mas/devops/templates/pipelinerun-restore.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-restore.yml.j2 @@ -20,11 +20,6 @@ spec: secret: secretName: pipeline-restore-configs params: - # Registry Credentials Secret - # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name - value: "mas-restore-secrets" - # Common Parameters - name: image_pull_policy value: IfNotPresent @@ -104,6 +99,10 @@ spec: - name: dro_contact_lastname value: "{{ dro_contact_lastname }}" {% endif %} + {% if ibm_entitlement_key is defined and ibm_entitlement_key != "" %} + - name: ibm_entitlement_key + value: "{{ ibm_entitlement_key }}" + {% endif %} {% if dro_namespace is defined and dro_namespace != "" %} - name: dro_namespace value: "{{ dro_namespace }}" @@ -149,6 +148,16 @@ spec: value: "{{ cert_manager_provider }}" {% endif %} + # Development Build Support + {% if artifactory_username is defined and artifactory_username != "" %} + - name: artifactory_username + value: "{{ artifactory_username }}" + {% endif %} + {% if artifactory_token is defined and artifactory_token != "" %} + - name: artifactory_token + value: "{{ artifactory_token }}" + {% endif %} + # Download Configuration {% if backup_archive_name is defined and backup_archive_name != "" %} - name: backup_archive_name diff --git a/src/mas/devops/templates/pipelinerun-update.yml.j2 b/src/mas/devops/templates/pipelinerun-update.yml.j2 index 2886d644..1370379e 100644 --- a/src/mas/devops/templates/pipelinerun-update.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-update.yml.j2 @@ -15,11 +15,6 @@ spec: pipeline: "0" params: - # Registry Credentials Secret - # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name - value: "mas-update-secrets" - {%- if image_pull_policy is defined and image_pull_policy != "" %} # Image Pull Policy @@ -33,6 +28,19 @@ spec: - name: mas_catalog_version value: "{{ mas_catalog_version }}" +{%- if ibm_entitlement_key is defined and ibm_entitlement_key != "" %} + # TODO: What even uses this, nothing in the update pipeline should be using this + - name: ibm_entitlement_key + value: "{{ ibm_entitlement_key }}" +{%- endif %} +{%- if artifactory_username is defined and artifactory_username != "" %} + # Enable development catalogs + # ------------------------------------------------------------------------- + - name: artifactory_username + value: "{{ artifactory_username }}" + - name: artifactory_token + value: "{{ artifactory_token }}" +{%- endif %} {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- diff --git a/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 b/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 index 11780e1e..2d451ab9 100644 --- a/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 +++ b/src/mas/devops/templates/pipelinerun-upgrade.yml.j2 @@ -15,11 +15,6 @@ spec: pipeline: "0" params: - # Registry Credentials Secret - # ------------------------------------------------------------------------- - - name: pipeline_registry_secret_name - value: "mas-upgrade-secrets" - {%- if image_pull_policy is defined and image_pull_policy != "" %} # Image Pull Policy @@ -35,12 +30,26 @@ spec: - name: mas_channel value: "{{ mas_channel }}" + # IBM Entitlement Key + # ------------------------------------------------------------------------- + - name: ibm_entitlement_key + value: "{{ ibm_entitlement_key }}" + {%- if skip_pre_check is defined and skip_pre_check != "" %} # Skip pre-check # ------------------------------------------------------------------------- - name: skip_pre_check value: "{{ skip_pre_check }}" {%- endif %} +{%- if artifactory_username is defined and artifactory_username != "" %} + + # Enable development catalogs + # ------------------------------------------------------------------------- + - name: artifactory_username + value: "{{ artifactory_username }}" + - name: artifactory_token + value: "{{ artifactory_token }}" +{%- endif %} {%- if storage_class_rwo is defined and storage_class_rwo != "" %} - name: storage_class_rwo value: "{{ storage_class_rwo }}" diff --git a/test/src/test_data.py b/test/src/test_data.py index c99c76f5..183d7918 100644 --- a/test/src/test_data.py +++ b/test/src/test_data.py @@ -32,7 +32,7 @@ def test_list_catalogs(): def test_get_newest_catalog_tag(): catalogTag = getNewestCatalogTag("amd64") # Reminder: update this test when adding a new catalog each month! - assert catalogTag == "v9-260924-amd64" + assert catalogTag == "v9-261007-amd64" def test_get_newest_catalog_tag_fail():